Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Attest Build Provenance #37

Merged
merged 2 commits into from
May 22, 2024
Merged

Attest Build Provenance #37

merged 2 commits into from
May 22, 2024

Conversation

GrantBirki
Copy link
Member

@GrantBirki GrantBirki commented May 22, 2024

Attest Build Provenance 🔒

Artifact attestations enable you to increase the supply chain security of your builds by establishing where and how your software was built.

This pull request publishes build attestations for the entitlements-app Gem. This allows us and all downstream consumers to use the built in gh cli command to securely validate when/where the Gem was built and that GitHub (the trusted source) created it.

Example 📸

Here is an example of how users of this gem can verify the gem after this PR lands:

$ gh attestation verify entitlements-app-X.X.X.gem --owner github

Read more about artifact attestations here 📚

@GrantBirki GrantBirki added the enhancement New feature or request label May 22, 2024
@GrantBirki GrantBirki self-assigned this May 22, 2024
Copy link
Member

@northrup northrup left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Neat! 🎉

@GrantBirki GrantBirki merged commit 4b76a33 into main May 22, 2024
17 checks passed
@GrantBirki GrantBirki deleted the attest-build-provenance branch May 22, 2024 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants